PT-2026-53861 · Suse · Rancher
CVSS v4.0
9.5
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Rancher versions 2.14.0 through 2.14.2
Rancher versions 2.13.0 through 2.13.6
Rancher versions 2.12.0 through 2.12.10
Rancher versions 2.11.0 through 2.11.14
Description
A SAML authentication replay issue exists in the Assertion Consumer Service (ACS) handler. The system fails to enforce the one-time use of SAML assertions, which are XML-based tokens used to communicate authentication and authorization information between an Identity Provider and a Service Provider. This missing replay protection allows an attacker who captures a valid SAML response—via man-in-the-middle attacks, compromised clients, or logs—to replay the response to authenticate without the victim's credentials. Successful exploitation can lead to unauthorized access, full cluster management takeover, and privilege escalation.
Recommendations
Upgrade Rancher versions 2.14.0 through 2.14.2 to 2.14.3.
Upgrade Rancher versions 2.13.0 through 2.13.6 to 2.13.7.
Upgrade Rancher versions 2.12.0 through 2.12.10 to 2.12.11.
Upgrade Rancher versions 2.11.0 through 2.11.14 to 2.11.15.
Exploit
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rancher